# Do not treat Threat Explorer's latest delivery location as the user's current folder

> What does an unknown or stale latest delivery location establish during an email investigation?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:09+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity
- Reading time: 2 minutes

## What you need to know

What does an unknown or stale latest delivery location establish during an email investigation?

## Potentially affected

Investigators interpreting original and latest delivery locations in Microsoft Defender for Office 365 Threat Explorer.

## DSE recommendation

Separate recorded delivery and security actions from any claim about the message's present user-managed location.

## Article

## Source facts

Threat Explorer’s Latest delivery location does not include end-user actions such as deletion or movement into an archive or PST file. Microsoft documents Unknown locations even when Delivery action says Delivered, for example when an Inbox rule moves mail into another default folder. Unknown can also occur when ZAP cannot find a message after delivery because it was moved or deleted. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about).

## Applicability

Use this interpretation when an investigation relies on Threat Explorer’s original or latest location fields. The relevant question is what those fields establish, not whether an unfamiliar value should automatically be escalated as a delivery failure.

## DSE recommendation

Separate recorded delivery and security actions from any claim about the message’s present user-managed location. Preserve the displayed location, delivery action and observation time together. If the response decision requires confirmation that a particular copy still exists, request appropriately authorized evidence for that specific question rather than treating the dashboard label as a live folder inventory. Avoid describing an unknown location as successful removal.

## Verification

In a controlled mailbox, compare the fields before and after a safe sample is moved by an end user. Inspect whether the investigation notes distinguish the observed security record from the independently established mailbox state. For a real case, keep uncertainty explicit until the necessary evidence is obtained. Record what was actually checked and do not infer that the recipient opened the message, retained a copy, or was protected merely from a location value.

## Official references

[Microsoft Learn: Threat Explorer field definitions](https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about). Source reviewed September 9, 2026.

## Primary reference

- Name: About Threat Explorer and Real-time detections in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not treat Threat Explorer's latest delivery location as the user's current folder,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
